Bugzilla – Bug 885209
VUL-0: CVE-2014-3499: docker: systemd socket activation results in privilege escalation
Last modified: 2018-12-14 15:09:56 UTC
CVE-2014-3499 It was found that the socket used to manage the Docker service was world readable and writable. A local user could use this flaw to escalate their privileges to root. References: https://bugzilla.redhat.com/show_bug.cgi?id=1111687 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3499 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3499
bugbot adjusting priority
Fixed with rev24 of the docker package.